Back to skill

Security audit

neon-auth

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a legitimate Neon Auth helper, but it asks the agent to load or install another online skill before use, so it should be reviewed carefully.

Use this only if you intend to work with Neon Auth and you trust the Neon skill source. Before allowing the agent to fetch or install the parent neon skill, review or pin that content if possible. Watch for auth migrations, domain changes, deploys, and environment updates, and do not let it replace an existing identity provider unless that is your explicit goal.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description says to use the skill for phrases like "add auth" and especially "add login," which are generic requests that can arise in many contexts. The description provides examples but does not clearly bound when the skill should not activate beyond a few migration cases, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
84% confidence
Finding

The skill instructs the agent to fetch or install a parent skill from an external URL/registry at runtime. This expands trust to additional unreviewed content and creates a skill-enumeration and supply-chain risk: an attacker who can influence that remote content, the installation source, or the resolution process could inject adversarial instructions into the agent workflow.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

FIRST: Use the parent neon skill for a Neon overview, getting started with Neon, Neon development best practices, and more.

If the neon skill is not installed, fetch it from https://neon.com/docs/ai/skills/neon/SKILL.md or install it with:

bash
neon skills -s neon -y

Static analysis

No suspicious patterns detected.